HTML/Infected.WebPage.Gen and Computer Sends Emails by Itself

Discussion in 'Malware Help - MG (A Specialist Will Reply)' started by Wuf4Wds, Mar 16, 2010.

  1. Wuf4Wds

    Wuf4Wds Private E-2

    Hi!

    About a month ago, my computer decided to send emails by itself (well, without my help). I read and followed the malware removal guide instructions. As far as I could tell, nothing of significance was found. Since "something" was sending email from my hotmail account, I figured "something" had to be there and I posted my logs for your review. You did not find anything either.

    I attributed the problems to a bad AVG update, and when I finally was able to uninstall AVG completely, I began using the free version of Avira AntiVir Personal. The automatic emails stopped.

    Since that time, the Avira AntiVir Guard has popped up several times. Each time, it was an htm file listed in C:\Documents and Settings\Terrie\Local Settings\Temporary Internet Files\Content.IE5\ folder. (The specific folder and file name changed with each notice). With each notice, I clicked deny access. When the guard popped up this week, I checked quarantine in hopes that would get rid of the problem.

    Within a couple of days, my computer started sending emails again. These emails have no subject line and the only thing inside the email is a weblink.

    Today, I ran another complete scan with Avira AntiVir and then ran cccleaner, superantispyware, malwrebytes. With the exception of a couple of "warnings" detected by Avira, nothing else was found. So, I go back online to see the next step in the removal process when the Avira guard popped back up with the HTML/Infected.WebPage.Gen detection. After reading the summary information at Avira, I wonder if this could be the culprit.

    I have run the programs as indicated. I’m not sure what happened with combofix. Shortly after finishing the scans, the screensaver kicked in and then I heard the windows critical stop sound. When the desktop reappeared, it seemed as though it was “stuck” mid re-boot. I waited about 10-15 minutes but nothing changed. So, I rebooted the computer. Now that I am attaching logs, I see there is no combofix log. There is no combofix log. Should I rerun it?

    So, to make a long story short (a little late for that ;) ), here are my questions:

    1. Is HTML/Infected.WebPage.Gen responsible for my hotmail account automatically sending out messages?
    2. Do I select "deny access" or "quarantine" whenever the guard pops up?
    3. Is the problem hiding somewhere on my computer or just a fluke that I'm hitting websites that have it?
    4. Why does my computer have an IE.5 directory when I'm running IE8?

    I’m sorry for being so long-winded but wanted to give you all the info since this “bug” is as aggravating as the car noise the mechanic never hears.

    Thank you so much for helping me.
     

    Attached Files:

  2. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Please double-click the RootRepeal.exe previously downloaded.

    * Select File then Scan
    * On the Select Drives form select drive C by "ticking" the box for drive C and click OK
    * When the scan is complete - highlight each of the following file(s) (one at a time if more then one is listed) by left clicking it. Then use right mouse click and select the Wipe File option only for each file.
    c:\documents and settings\terrie\local settings\temp\~df2a7c.tmp
    c:\documents and settings\terrie\local settings\temp\~df3660.tmp
    c:\documents and settings\terrie\local settings\temp\~df4169.tmp
    c:\documents and settings\terrie\local settings\temp\~df6d0b.tmp
    c:\documents and settings\terrie\local settings\temp\~df8b9f.tmp
    c:\documents and settings\terrie\local settings\temp\~dfa5e0.tmp
    c:\documents and settings\terrie\local settings\temp\~dfbee.tmp
    C:\Documents and Settings\Terrie\Local Settings\Temporary Internet Files\Content.IE5\1U0ZG8IH\search[1].txt
    c:\documents and settings\terrie\local settings\temporary internet files\content.ie5\9ea5jn17\search[2].htm
    C:\Documents and Settings\Terrie\Local Settings\Temporary Internet Files\Content.IE5\FW2Q7W3O\search[2]
    C:\Documents and Settings\Terrie\Local Settings\Temporary Internet Files\Content.IE5\JEXX21QN\IS[2]
    C:\Documents and Settings\Terrie\Local Settings\Temporary Internet Files\Content.IE5\OH27Z7KZ\awt_analytics[1].js
    C:\Documents and Settings\Terrie\Local Settings\Temporary Internet Files\Content.IE5\PJCAY5ZU\comment[1].js
    C:\Documents and Settings\Terrie\Local Settings\Temporary Internet Files\Content.IE5\PJCAY5ZU\leo2t[1].png
    C:\Documents and Settings\Terrie\Local Settings\Temporary Internet Files\Content.IE5\UGVOIBD3\MicrosoftAjax[2].js
    C:\Documents and Settings\Terrie\Local Settings\Temporary Internet Files\Content.IE5\UGVOIBD3\WebResource[1].css
    C:\Documents and Settings\Terrie\Local Settings\Temporary Internet Files\Content.IE5\UGVOIBD3\WebResource[2].css
    * After Wiping all files, immediately reboot your pc!

    I know you are using Hotmail, but the below guide is still appropriate:
    Malware detected in email databases has to be cleaned up by you. You have a few choices:

    1. delete the whole file which is not an option you normally want to use
    2. load the email folder that contains the infection and delete ALL unnecessary emails (hoping to remove the problem email) and then use the Mailbox Cleanup option to delete all old emails. Then compact the Outlook database to permanently remove data. See http://support.microsoft.com/kb/196990 If you do not cleanup and compact the databases, the deleted emails may still be leaving hidden information in the database that you just cannot see but a scanner may still pickup on it.
    3. create a new folder and move only emails you really need into the new folder and then delete the infected folder.

    Make sure you clean out your temp internet files!!

    Tell me what issues you still have.
     
  3. Wuf4Wds

    Wuf4Wds Private E-2

    Hi Tim,

    I followed your instructions and everything appeared to be fine...until today. It has started again. This is the reason I had not responded before now--I was afraid the issue would popup again as there appears to be some sort of pattern.

    As for the pattern, I'm not sure if it is a particular date or a particular time span; I just know that it restarts sending emails about a month after it stops sending the emails.

    The only possible conflict with me following your instructions could be the change in language on WindowsLive and Outlook. There is a mailbox cleanup option but no compact option--at least not that I can find. That being said, if there is actual compact option and it is not within the cleanup option, then I accidentally did not follow your instructions. I did check out the site for which you provided the link, and as far as I could tell, I followed instructions.

    Any help you can provide will be GREATLY appreciated! I'm beginning to lose friends as they are scared they will catch something from these emails.

    Thanks! I'm anxiously waiting to hear from you.

    Wuf4Wds
     
  4. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Since it has been a month since you last posted, we need to have you re-download the scanning tools and attach the new logs. I will want to see:
    SAS
    MBAM
    RootRepeal
    ComboFix
    C:\MGLogs.zip

    Is this again concerning your Hotmail account? If so, have you removed any emails that contain attachments that you may have clicked on? Have you removed any emails with links? What have you done to stop this from occurring?
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds